Sicherheit
Security
All tracked CVEs and security advisories — sorted by date or severity. Each entry links to the official source. The plain-text explanations are generated automatically — the source remains authoritative.
| CVE / GHSA | Item | Vertical | Severity | Date |
|---|---|---|---|---|
| CVE-2026-5906 Source A vulnerability in Google Chrome's address bar on Android allows attackers to display fake URLs, potentially deceiving users about which website they are actually visiting. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-5902 Source A vulnerability in Google Chrome's media processing on Android allows attackers who have already compromised the browser renderer to corrupt media metadata, potentially enabling further damage to the system. |
Android | OS & platform | Critical | 05.06.2026 |
| CVE-2026-5288 Source A memory management vulnerability in Chrome's WebView component on Android allows attackers who have already compromised the renderer process to potentially escape the security sandbox and gain broader system access. |
Android | OS & platform | Critical | 05.06.2026 |
| CVE-2026-5278 Source A vulnerability in Google Chrome's Web MIDI feature on Android allows attackers to execute malicious code through crafted web pages, potentially gaining control over the device. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-4439 Source A vulnerability in Chrome's WebGL component on Android allows attackers to access memory outside permitted boundaries through specially crafted web pages, potentially bypassing the browser's security barriers. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-4250 Source An Android app called Albert Health stores Google Cloud access credentials unprotected in a file, allowing local attackers to potentially read these credentials. |
Android | OS & platform | Low | 05.06.2026 |
| CVE-2026-3937 Source A security vulnerability in Google Chrome for Android allows attackers to manipulate the downloads user interface and deceive users through fake displays on malicious websites. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-3936 Source A memory management vulnerability in Chrome's WebView component on Android allows attackers to execute malicious code or crash the system through specially crafted web pages. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-3932 Source A security flaw in Google Chrome for Android allowed attackers to bypass PDF navigation restrictions and redirect users to unwanted websites through malicious web pages. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-3925 Source A security flaw in Google Chrome for Android allowed attackers to display fake user interfaces to deceive users and potentially steal sensitive information. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-3537 Source A flaw in Chrome's PowerVR component on Android allows attackers to cause memory corruption and potentially execute malicious code through specially crafted web pages. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-20700 Source A memory corruption flaw in iOS allows attackers with memory write access to execute arbitrary code. Apple has received reports of targeted attacks against specific individuals exploiting this vulnerability. |
iOS | OS & platform | High | 05.06.2026 |
| CVE-2026-46446 Source A SQL injection vulnerability in SOGo software allows attackers to inject malicious database commands when PostgreSQL or MariaDB is used and passwords are stored in cleartext. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-46445 Source A vulnerability in SOGo (not PostgreSQL itself) allows SQL injection attacks when PostgreSQL is used as the database, potentially enabling attackers to unauthorized access or manipulate data. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-42032 Source A vulnerability in CKAN (a data management system) allows attackers to bypass authorization controls and access private data as well as PostgreSQL system information. |
PostgreSQL | OS & platform | Critical | 05.06.2026 |
| CVE-2026-42031 Source A vulnerability in CKAN (a data management system) allows attackers to inject malicious SQL code, enabling access to confidential data and PostgreSQL system information. |
PostgreSQL | OS & platform | Critical | 05.06.2026 |
| CVE-2026-32687 Source A SQL injection vulnerability in the postgrex PostgreSQL driver for Elixir allows attackers to execute arbitrary SQL commands when they can influence channel names in notification functions, potentially leading to data loss or unauthorized database access. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-7428 Source A vulnerability in Google Cloud AlloyDB for PostgreSQL caused database clusters created via Terraform or REST API to receive insecure default passwords, allowing attackers with network access to gain full administrative database access. |
PostgreSQL | OS & platform | Critical | 05.06.2026 |
| CVE-2026-7815 Source A security vulnerability in pgAdmin 4 allows authenticated users to inject malicious SQL code and thereby execute arbitrary commands on the database server. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-7814 Source A security vulnerability in pgAdmin 4 allows attackers to execute malicious JavaScript code in web browsers by using specially crafted names for PostgreSQL objects. |
PostgreSQL | OS & platform | Medium | 05.06.2026 |
| CVE-2026-41889 Source A security vulnerability in the pgx PostgreSQL driver for Go allows SQL injection attacks under specific conditions involving special string literals, enabling attackers to inject malicious database commands. |
PostgreSQL | OS & platform | Critical | 05.06.2026 |
| CVE-2026-41496 Source A vulnerability in PraisonAI allows SQL injection attacks through unvalidated parameters in multiple database connections, enabling attackers to manipulate databases or access sensitive data. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-29090 Source A SQL injection vulnerability in Rucio allows authenticated users to execute arbitrary SQL commands against the PostgreSQL database. This can lead to exposure of sensitive data, data manipulation, or even code execution. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-29080 Source A SQL injection vulnerability in Rucio allows authenticated users to execute arbitrary SQL commands against the Oracle database, potentially stealing or manipulating all managed data, authentication tokens, and password hashes. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-33324 Source SQLBot, a text-to-SQL system, passes user input unfiltered to an AI model and executes the generated SQL commands without validation. Attackers can exploit this to execute arbitrary SQL commands and, when connected to PostgreSQL, even run code on the server. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-42198 Source A vulnerability in the PostgreSQL JDBC driver allows malicious servers to freeze client computers through extremely CPU-intensive authentication, blocking CPU cores and exhausting connection pools. affects: ≥42.2.0 <42.7.11 |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-3960 Source A critical security flaw in H2O-3 software allows attackers to execute arbitrary code on the server without authentication by exploiting PostgreSQL-specific parameters in the REST API. |
PostgreSQL | OS & platform | Critical | 05.06.2026 |
| CVE-2026-41167 Source A security vulnerability in Jellystat software allows authenticated users to inject malicious SQL code, enabling them to steal sensitive data from the database or even execute arbitrary commands on the PostgreSQL server. |
PostgreSQL | OS & platform | Critical | 05.06.2026 |
| CVE-2026-40906 Source A vulnerability in ElectricSQL allows authenticated users to read, modify, or destroy the entire PostgreSQL database through manipulated sorting parameters in the API. |
PostgreSQL | OS & platform | Critical | 05.06.2026 |
| CVE-2026-39946 Source OpenBao, a secrets management system, fails to properly quote database schema names when revoking PostgreSQL privileges, which can cause revocation failures or rarely enable SQL injection attacks. |
PostgreSQL | OS & platform | Medium | 05.06.2026 |
| CVE-2026-34977 Source A vulnerability in Aperi'Solve allows attackers to gain root access to the server through manipulated JPEG passwords without authentication, potentially compromising the PostgreSQL database and other system components. |
PostgreSQL | OS & platform | Critical | 05.06.2026 |
| CVE-2026-34612 Source A vulnerability in the Kestra orchestration platform allows authenticated users to execute arbitrary commands on the server by visiting a crafted link, as SQL injection attacks are possible through PostgreSQL. |
PostgreSQL | OS & platform | Critical | 05.06.2026 |
| CVE-2026-34455 Source Hi.Events, an open-source event management platform, contains a SQL injection vulnerability in multiple repository classes that pass user input directly to the database without validation, allowing attackers to execute malicious SQL commands. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-32286 Source A vulnerability in PostgreSQL allows malicious servers to crash client applications by sending manipulated data messages with invalid field lengths. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-33713 Source A vulnerability in the n8n workflow automation platform allows authenticated users to manipulate or delete data in PostgreSQL databases through SQL injection attacks. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-33539 Source Parse Server, a Node.js backend application, contains a SQL injection vulnerability in PostgreSQL connections. Attackers with master key access can execute arbitrary SQL commands and escalate their privileges from application level to database level access. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-32950 Source A security vulnerability in SQLBot allows authenticated users to inject malicious SQL commands through manipulated Excel files, enabling them to gain complete control over the server. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-32622 Source A security flaw in SQLBot allows authenticated users to inject malicious content through Excel uploads and manipulate the AI system to execute dangerous PostgreSQL commands, ultimately gaining remote access to the server. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-32628 Source A SQL injection vulnerability in AnythingLLM allows users to execute arbitrary SQL commands on connected databases because table names are unsafely inserted into queries without proper sanitization. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-32248 Source Parse Server, a backend software for Node.js, contains a critical security vulnerability that allows attackers to take over any user account without authentication by sending specially crafted login requests. |
PostgreSQL | OS & platform | Critical | 05.06.2026 |
| CVE-2026-32234 Source Parse Server, a Node.js backend software, contains a SQL injection vulnerability when using PostgreSQL databases. Attackers with master key access can inject malicious SQL commands through crafted field names in queries, bypassing Parse Server to directly attack the database. |
PostgreSQL | OS & platform | Medium | 05.06.2026 |
| CVE-2026-31872 Source A security vulnerability in Parse Server allows attackers to bypass protected database field restrictions using dot-notation queries, potentially exposing sensitive data that should be protected. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-31871 Source A critical SQL injection vulnerability in Parse Server allows attackers to execute arbitrary SQL commands in PostgreSQL databases through crafted field names, bypassing security controls. |
PostgreSQL | OS & platform | Critical | 05.06.2026 |
| CVE-2026-31856 Source A SQL injection vulnerability in Parse Server allows attackers to execute arbitrary SQL commands through the REST API and thereby read all data from PostgreSQL databases. |
PostgreSQL | OS & platform | Critical | 05.06.2026 |
| CVE-2026-31840 Source A vulnerability in Parse Server allows SQL injection attacks against PostgreSQL databases through improper handling of dot-notation field names in sort and other query parameters, enabling attackers to inject malicious SQL commands. |
PostgreSQL | OS & platform | Critical | 05.06.2026 |
| CVE-2025-13957 Source PostgreSQL contains hard-coded credentials that could allow attackers with administrator access and known database passwords to steal information or execute malicious code when SOCKS proxy functionality is enabled. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-25041 Source A vulnerability in the Budibase low-code platform allows attackers to execute malicious commands through unsafe PostgreSQL database connection parameters, as user inputs are not properly sanitized before shell execution. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-30860 Source A security vulnerability in WeKnora, a document understanding framework, allows attackers to execute malicious code on the PostgreSQL database server by bypassing SQL injection protections. |
PostgreSQL | OS & platform | Critical | 05.06.2026 |
| CVE-2026-29089 Source A security vulnerability in the TimescaleDB extension for PostgreSQL allows malicious users to create custom functions that override built-in PostgreSQL functions, potentially enabling arbitrary code execution during extension upgrades. |
PostgreSQL | OS & platform | High | 05.06.2026 |
| CVE-2026-27005 Source Chartbrew, a web application for data visualization, contains an SQL injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL commands into connected databases, potentially reading, modifying, or deleting data. |
PostgreSQL | OS & platform | Critical | 05.06.2026 |